Skip to content
HashiCorpCVE-2026-87993

HashiCorp Tooling: information disclosure

High7.7CVE-2026-87993 · Published Sep 10, 2026

The consul-template library is vulnerable to an information disclosure issue in its error handling path that may allow Vault secret values to appear in template error messages, log output, and downstream surfaces such as Nomad task events. This vulnerability (CVE-2026-87993) is fixed in consul-template 0.43.0.

HashiCorp advisory

Affected versions

PackageAffectedFixed in
Tooling
Product
>= 0.27.2, < 0.43.00.43.0
Details and references

More HashiCorp advisories

All HashiCorp
Advisory
HashiCorp Shared library: privilege escalation
Medium6.7Sep 15
Consul and Consul Enterprise are vulnerable to an authorization bypass in the...
High7.1Sep 10
HashiCorp Consul: improper authorization
High8.3Sep 10
HashiCorp Consul: denial of service
Medium6.5Sep 10
HashiCorp Consul: improper authorization
Medium5.4Sep 10
HashiCorp Vault: insecure direct object reference
Medium6.8Aug 24

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.